class Shop::PicturesController < ShopController
  skip_before_action :verify_authenticity_token, :only => [:create]

  def create
    @picture = Picture.new picture_params
    if @picture.save
      render :json => {
        "success" => true,
        "msg" => "上传成功.", # optional
        "file_path" => @picture.image.url
      }
    else
      render :json => {
        "success" => false,
        "msg" => "上传失败.", # optional
        "file_path" => ""
      }
    end
  end

  private

  def picture_params
    params.require(:picture).permit(:image, :sort)
  end
end
